Instagram Post Sync Goes Live 📸🔄
June 3, 2026
If you plan to use Xtreme Automator® for marketing/lead generation without the HIPAA add-on, you must keep the platform PHI-free. This article shows exactly what to collect (safe) and what to avoid (risky).
PHI is information that can identify a person and relates to healthcare services or condition.
In practice, “Name + what I need therapy for” can become PHI once tied to your practice.
Use these fields for marketing forms:
Use broad categories that don’t imply diagnosis:
“New Client Appointment”
“Returning Client Scheduling”
“Billing Question”
“General Question”
Do not include open-ended prompts like:
Avoid any form field that captures:
The single biggest PHI risk is a “Message” field. If you keep one, use both:
Short character limit (example: 120–200 chars)
Clear warning text directly above it
For your privacy, please do not include medical or clinical details here.
We’ll collect sensitive information through our secure patient portal.
Use the form to capture contact info, then:
Auto-reply: “Please share details through our secure portal”
Include a link to the portal intake form
This keeps Xtreme Automator® PHI-free while still converting leads.
Before publishing any form:
No clinical questions
No file upload fields
No open “tell us what’s going on” message field (or limited + disclaimer)
Automated reply directs clients to secure portal for sensitive details
Team trained not to add clinical info into Notes/Custom Fields